From fba201c9953a490da914b09e09eaaa697a4b36e1 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Wed, 5 Nov 2025 06:00:39 +0900 Subject: container/std: relocate rule types This enables its use in hst for #15. Signed-off-by: Ophestra --- container/std/seccomp.go | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) create mode 100644 container/std/seccomp.go (limited to 'container/std') diff --git a/container/std/seccomp.go b/container/std/seccomp.go new file mode 100644 index 00000000..f3189ca5 --- /dev/null +++ b/container/std/seccomp.go @@ -0,0 +1,38 @@ +package std + +type ( + // ScmpUint is equivalent to C.uint. + ScmpUint uint32 + // ScmpInt is equivalent to C.int. + ScmpInt int32 + + // ScmpSyscall represents a syscall number passed to libseccomp via [NativeRule.Syscall]. + ScmpSyscall ScmpInt + // ScmpErrno represents an errno value passed to libseccomp via [NativeRule.Errno]. + ScmpErrno ScmpInt + + // ScmpCompare is equivalent to enum scmp_compare; + ScmpCompare ScmpUint + // ScmpDatum is equivalent to scmp_datum_t. + ScmpDatum uint64 + + // ScmpArgCmp is equivalent to struct scmp_arg_cmp. + ScmpArgCmp struct { + // argument number, starting at 0 + Arg ScmpUint + // the comparison op, e.g. SCMP_CMP_* + Op ScmpCompare + + DatumA, DatumB ScmpDatum + } + + // A NativeRule specifies an arch-specific action taken by seccomp under certain conditions. + NativeRule struct { + // Syscall is the arch-dependent syscall number to act against. + Syscall ScmpSyscall + // Errno is the errno value to return when the condition is satisfied. + Errno ScmpErrno + // Arg is the optional struct scmp_arg_cmp passed to libseccomp. + Arg *ScmpArgCmp + } +) -- cgit v1.3.1